Skip to main content
Cloud / STACKIT / Products / STACKIT Confidential Kubernetes - Encrypted Containers

STACKIT Confidential Kubernetes - Encrypted Containers

STACKIT Confidential Kubernetes: hardware-isolated Kubernetes clusters built on Constellation for regulated workloads.

Confidential
Pricing Model Individual quote on request (cost of underlying Confidential Server included)
Availability German STACKIT data centers
Data Sovereignty 100% German data centers, GDPR compliant
Reliability SLA as published by the provider SLA

What is STACKIT Confidential Kubernetes?

STACKIT Confidential Kubernetes is a confidential computing platform that allows containerized applications to run in a cluster shielded from the underlying cloud infrastructure. It is built on Constellation, an open-source Kubernetes engine developed by Edgeless Systems, whose nodes run as Confidential Virtual Machines (CVMs) with hardware-based memory encryption. This keeps data protected even while it is being processed in memory and allows its integrity to be cryptographically verified.

Core Features

  • Hardware-isolated cluster nodes based on Confidential Virtual Machines
  • Transparent encryption of network and storage
  • Remote attestation for individual nodes joining the cluster
  • Proof of integrity for the entire cluster via a hardware-bound certificate
  • Automated, transparent key management within the isolated environment

Typical Use Cases

Regulated industries: Healthcare, finance, and the public sector with strict data protection and auditability requirements.

Cloud migration of sensitive workloads: Organizations moving on-premises workloads with private-cloud-level security requirements into the public cloud.

Trustworthy SaaS offerings: Providers who want to cryptographically prove the isolation and integrity of their platform to customers.

Benefits

  • Closes the gap between encryption at rest/in transit and encryption during processing
  • Operated in German STACKIT data centers, GDPR compliant
  • Verifiable security through remote attestation rather than pure trust in the provider
  • Built on established open-source technology (Constellation)

Integration with innFactory

As an official STACKIT partner, innFactory supports the introduction of Confidential Kubernetes: from architecture and migration of existing workloads to ongoing operations and cost optimization.

Available Tiers & Options

Typical Use Cases

Regulated industries (healthcare, finance, public sector)
Migrating sensitive on-premises workloads to the cloud
Trustworthy SaaS offerings with verifiable isolation
Workloads with strict data protection and compliance requirements

Frequently Asked Questions

What is STACKIT Confidential Kubernetes?

A confidential computing platform that lets customers run containerized applications in a cluster shielded from the underlying cloud infrastructure at the hardware level. It is built on Constellation, an open-source Kubernetes engine by Edgeless Systems, running on Confidential Virtual Machines (CVMs).

How does the encryption work?

All Kubernetes nodes run inside encrypted CVMs. Network and storage are encrypted transparently, protecting data at rest, in transit, and while being processed in memory.

What does STACKIT Confidential Kubernetes cost?

The service is currently offered on a customer-specific basis; a concrete quote is obtained through STACKIT sales. The cost of the underlying Confidential Server is already included.

How can I verify the integrity of my cluster?

Each new node is verified via remote attestation before it is granted access to the cluster. The integrity of the entire cluster can additionally be proven using a hardware-bound certificate.

What use cases fit Confidential Kubernetes?

Regulated industries with strict compliance requirements, migrating sensitive workloads to the cloud, and providers who want to increase the trustworthiness of their SaaS offering through verifiable isolation.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Ready to start with STACKIT Confidential Kubernetes - Encrypted Containers?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation